Information Security based on ISO 27001/ISO 27002

Information Security based on ISO 27001/ISO 27002

4.11 - 1251 ratings - Source

Information is the currency of the information age and in many cases is the most valuable asset possessed by an organisation. Information security management is the discipline that focuses on protecting and securing these assets against the threats of natural disasters, fraud and other criminal activity, user error and system failure. This Management Guide provides an overview of the two international information security standards, ISO/IEC 27001 and ISO 27002. These standards provide a basis for implementing information security controls to meet an organisationa€™s own business requirements as well as a set of controls for business relationships with other parties. This Guide provides: An introduction and overview to both the standards The background to the current version of the standards Links to other standards, such as ISO 9001, BS25999 and ISO 20000 Links to frameworks such as CobiT and ITIL Above all, this handy book describes how ISO 27001 and ISO 27002 interact to guide organizations in the development of best practice information security management systems.ISO 27001 describes the minimum documentation that should be included in the ISMS (to meet the Standarda#39;s requirement that ... Together, these form the ISMS policy manual a€c evidence of the actions undertaken by the organization and itsanbsp;...

Title:Information Security based on ISO 27001/ISO 27002
Author:Alan Calder
Publisher:Van Haren - 2009-07-31


You Must CONTINUE and create a free account to access unlimited downloads & streaming